Known vulnerabilities in IBM Process Mining - page 15

Software CPE: cpe:2.3:a:ibm_corporation:ibm_process_mining:*:*:*:*:*:*:*:*
Total vulnerabilities: 318
Public exploits: 38
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Process Mining IBM Process Mining is affected by 318 known vulnerabilities: 1 critical, 66 high, 197 medium, 54 low Critical High Medium Low

Vulnerabilities (318)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU49369 - Deserialization of Untrusted Data
CVE-2020-36180
CWE-502 High
Available
No
1.12.0.4 07.01.2021 SB2021011105
SB2021042826
SB2021050708
and 16 more
#VU49370 - Deserialization of Untrusted Data
CVE-2020-36182
CWE-502 High
No
No
1.12.0.4 07.01.2021 SB2021011105
SB2021042826
SB2021050708
and 17 more
#VU49372 - Deserialization of Untrusted Data
CVE-2020-36181
CWE-502 High
No
No
1.12.0.4 07.01.2021 SB2021011105
SB2021042826
SB2021050708
and 17 more
#VU49378 - Deserialization of Untrusted Data
CVE-2020-35728
CWE-502 High
Available
No
1.12.0.4 27.12.2020 SB2021011105
SB2021042826
SB2021050708
and 15 more
#VU48979 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2020-25649
CWE-611 Medium
No
No
1.12.0.4 03.12.2020 SB2020121510
SB2021020321
SB2021042112
and 68 more
#VU47105 - Deserialization of Untrusted Data
CVE-2020-24750
CWE-502 High
Available
No
1.12.0.4 17.09.2020 SB2020092506
SB2020100512
SB2021012013
and 28 more
#VU29128 - Deserialization of Untrusted Data
CVE-2020-14195
CWE-502 High
Available
No
1.12.0.4 18.06.2020 SB2020061806
SB2020070320
SB2020102703
and 24 more
#VU27032 - Deserialization of Untrusted Data
CVE-2020-11620
CWE-502 High
No
No
1.12.0.4 20.04.2020 SB2020030909
SB2020052628
SB2020073033
and 15 more
#VU27031 - Deserialization of Untrusted Data
CVE-2020-11619
CWE-502 High
No
No
1.12.0.4 20.04.2020 SB2020030909
SB2020052628
SB2020073033
and 15 more
#VU26489 - Deserialization of Untrusted Data
CVE-2020-11112
CWE-502 High
No
No
1.12.0.4 01.04.2020 SB2020030909
SB2020042318
SB2020073033
and 16 more
#VU25834 - Deserialization of Untrusted Data
CVE-2019-14893
CWE-502 High
No
No
1.12.0.4 09.03.2020 SB2020030911
SB2020031901
SB2022060909
and 15 more
#VU25830 - Deserialization of Untrusted Data
CVE-2020-9546
CWE-502 High
No
No
1.12.0.4 09.03.2020 SB2020030909
SB2020071523
SB2020071620
and 31 more
#VU25469 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-8840
CWE-94 Medium
Available
No
1.12.0.4 19.02.2020 SB2020021921
SB2020022615
SB2020061106
and 18 more
#VU21594 - Improper input validation
CVE-2019-17267
CWE-20 Medium
No
No
1.12.0.4 07.10.2019 SB2019100710
SB2019102422
SB2019120206
and 19 more
#VU21593 - Improper input validation
CVE-2019-16943
CWE-20 Medium
No
No
1.12.0.4 07.10.2019 SB2019100711
SB2019100716
SB2019120206
and 34 more
#VU21470 - Improper input validation
CVE-2019-10202
CWE-20 High
No
No
1.12.0.4 01.10.2019 SB2019100116
SB2019100117
SB2019100118
and 24 more
#VU21135 - Exposure of sensitive information to an unauthorized actor
CVE-2019-14540
CWE-200 Medium
Available
No
1.12.0.4 16.09.2019 SB2019091616
SB2019100716
SB2019102422
and 23 more
#VU19933 - Permissions, Privileges, and Access Controls
CVE-2019-14379
CWE-264 High
No
No
1.12.0.4 05.08.2019 SB2019091307
SB2019092703
SB2019100116
and 33 more
#VU17776 - Server-Side Request Forgery (SSRF)
CVE-2018-14721
CWE-918 Low
No
No
1.12.0.4 19.02.2019 SB2018121501
SB2019052407
SB2019092703
and 23 more
#VU17053 - Permissions, Privileges, and Access Controls
CVE-2018-14718
CWE-264 High
No
No
1.12.0.4 17.01.2019 SB2019011703
SB2019052407
SB2019091718
and 29 more


Showing elements 281 - 300 out of 318